CVE-2021-2329: High severity oracle xml database vulnerability
Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in takeover of Oracle XML DB. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-2329.
What is the title of the vulnerability?
The title of the vulnerability is 'Vulnerability in the Oracle XML DB component of Oracle Database Server.'
What versions of Oracle Database Server are affected?
Versions 12.1.0.2, 12.2.0.1, and 19c of Oracle Database Server are affected.
What privileges does the high privileged attacker need?
The high privileged attacker needs 'Create Any Procedure' and 'Create Public Synonym' privileges.
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.2.